Clop ransomware is now extorting 66 Cleo data-theft victims

Share:

The Clop ransomware gang started to extort victims of its Cleo data theft attacks and announced on its dark web portal that 66 companies have 48 hours to respond to the demands.

The cybercriminals announced that they are contacting those companies directly to provide links to a secure chat channel for conducting ransom payment negotiations. They also provided email addresses where victims can reach out themselves.

In the notification on their leak site, Clop lists 66 partial names of companies that did not engage the hackers for negotiations. If these companies continue to ignore, Clop threatens to disclose their full name in 48 hours.

The hackers note that the list represents only victims that have been contacted but did not respond to the message, suggesting that the list of affected companies may be larger.

Clop achieves another major breach

The Cleo data theft attack represents another major success for Clop, who leveraged leveraging a zero-day vulnerability in Cleo LexiCom, VLTransfer, and Harmony products to steal data from the networks of breached companies.

In the past, Clop ransomware accessed company networks by exploiting zero-day vulnerabilities in Accellion FTA secure file transfer platform, GoAnywhere MFT platform, and MOVEit Transfer platform.

The gang is also responsible for another hacking spree targeting companies running the SolarWinds Serv-U FTP software.

The zero-day flaw exploited this time is now tracked as CVE-2024-50623 and it allows a remote attacker to perform unrestricted file uploads and downloads, leading to remote code execution.

A fix is available for Cleo Harmony, VLTrader, and LexiCom version 5.8.0.21 and the vendor warned in a private advisory that hackers were exploiting it to open reverse shells on compromised networks.

Earlier this month, Huntress publicly disclosed that the vulnerability was actively exploited and sounded the alarm that the vendor’s fix could be bypassed. The researchers also provided a proof-of-concept (PoC) exploit to demonstrate their findings.

A few days later, Clop ransomware confirmed to BleepingComputer that it was responsible for exploiting CVE-2024-50623.

The infamous ransomware group declared that data from previous attacks will now be deleted from its platform as it focuses on the new extortion round.

In an email to BleepingComputer, Macnica researcher Yutaka Sejiyama said that even with the incomplete company names that Clop published on its data leak site, it is possible to identify some of the victims by simply cross checking the hacker’s hints with owners of Cleo servers exposed on the public web.

At this time, it is unknown how many companies have been compromised by Clop’s latest attack wave, but Cleo claims that its software is used by more than 4,000 organizations worldwide.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
9:56 pm, Jan 16, 2025
weather icon 7°C
L: 7° | H: 8°
overcast clouds
Humidity: 85 %
Pressure: 1035 mb
Wind: 6 mph
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:58 am
Sunset: 4:21 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 9:00 pm
weather icon
7° | 8°°C 0 mm 0% 5 mph 96 % 1035 mb 0 mm/h
Sat Jan 18 9:00 pm
weather icon
2° | 7°°C 0 mm 0% 4 mph 83 % 1034 mb 0 mm/h
Sun Jan 19 9:00 pm
weather icon
2° | 6°°C 0 mm 0% 7 mph 88 % 1023 mb 0 mm/h
Mon Jan 20 9:00 pm
weather icon
3° | 7°°C 0 mm 0% 7 mph 93 % 1021 mb 0 mm/h
Tue Jan 21 9:00 pm
weather icon
3° | 7°°C 0 mm 0% 3 mph 96 % 1021 mb 0 mm/h
Tomorrow 12:00 am
weather icon
4° | 6°°C 0 mm 0% 3 mph 89 % 1035 mb 0 mm/h
Tomorrow 3:00 am
weather icon
4° | 5°°C 0 mm 0% 4 mph 93 % 1034 mb 0 mm/h
Tomorrow 6:00 am
weather icon
3° | 3°°C 0 mm 0% 3 mph 96 % 1035 mb 0 mm/h
Tomorrow 9:00 am
weather icon
3° | 3°°C 0 mm 0% 3 mph 95 % 1035 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
7° | 7°°C 0 mm 0% 5 mph 77 % 1035 mb 0 mm/h
Tomorrow 3:00 pm
weather icon
7° | 7°°C 0 mm 0% 3 mph 76 % 1034 mb 0 mm/h
Tomorrow 6:00 pm
weather icon
5° | 5°°C 0 mm 0% 3 mph 88 % 1034 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
4° | 4°°C 0 mm 0% 3 mph 86 % 1034 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€97,136.98
0.23%
Ethereum(ETH)
€3,224.63
-3.45%
XRP(XRP)
€3.20
8.32%
Tether(USDT)
€0.97
-0.03%
Solana(SOL)
€206.47
4.51%
Dogecoin(DOGE)
€0.369982
0.75%
USDC(USDC)
€0.97
0.01%
Shiba Inu(SHIB)
€0.000021
-0.80%
Pepe(PEPE)
€0.000017
-2.17%
Peanut the Squirrel(PNUT)
€0.59
-4.65%
Scroll to Top